CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,108 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
170,687 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-0787 EXP | wimpy_trackplays.php in Plaino Wimpy MP3 Player, possibly 5.2 and earlier, allows remote attackers to insert arbitrary strings into trackme.txt via th… | Patch early | 4.0 medium | 2.2% | 2006-02-19 |
| CVE-2007-6202 EXP | SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier allows remote attackers to execute arbitrary SQL comm… | Patch early | 6.8 medium | 2.2% | 2007-12-01 |
| CVE-2013-4200 EXP | The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs start… | Patch early | 5.8 medium | 2.2% | 2014-01-21 |
| CVE-2007-0121 EXP | Cross-site scripting (XSS) vulnerability in search.asp in RI Blog 1.3 allows remote attackers to inject arbitrary web script or HTML via the q paramet… | Patch early | 6.8 medium | 2.2% | 2007-01-09 |
| CVE-1999-0908 EXP | Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_ent… | Patch early | 5.0 medium | 2.2% | 1999-09-23 |
| CVE-2001-0407 EXP | Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whos… | Patch early | 4.6 medium | 2.2% | 2001-06-27 |
| CVE-2008-0751 EXP | Cross-site scripting (XSS) vulnerability in the Freetag before 2.96 plugin for S9Y Serendipity, when using Internet Explorer 6 or 7, allows remote att… | Patch early | 4.3 medium | 2.2% | 2008-02-13 |
| CVE-2004-2563 EXP | Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and database information, and conduct cro… | Patch early | 5.8 medium | 2.2% | 2004-12-31 |
| CVE-2007-6135 EXP | Cross-site scripting (XSS) vulnerability in phpslideshow.php in PHPSlideShow 0.9.9.2, and possibly earlier, allows remote attackers to inject arbitrar… | Patch early | 4.3 medium | 2.2% | 2007-11-27 |
| CVE-2013-4664 EXP | SPBAS Business Automation Software 2012 has XSS. | Patch early | 6.1 medium | 2.2% | 2019-12-27 |
| CVE-2014-8995 EXP | SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the UserId cookie. | Patch early | 5.0 medium | 2.2% | 2014-11-20 |
| CVE-2009-2329 EXP | KerviNet Forum 1.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) admin/head.php, or (2) voting_diagr… | Patch early | 5.0 medium | 2.2% | 2009-07-05 |
| CVE-2009-4961 EXP | Lanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls the phpinfo function. | Patch early | 5.0 medium | 2.2% | 2010-07-28 |
| CVE-2007-1873 EXP | Cross-site scripting (XSS) vulnerability in Mephisto 0.7.3 allows remote attackers to inject arbitrary web script or HTML via the q parameter to the s… | Patch early | 4.3 medium | 2.2% | 2007-04-13 |
| CVE-2001-0114 EXP | statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter. | Patch early | 5.0 medium | 2.2% | 2001-03-12 |
| CVE-2005-3329 EXP | Cross-site scripting (XSS) vulnerability in RSA Authentication Agent for Web 5.3 and earlier allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 2.2% | 2005-10-27 |
| CVE-2008-5569 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PHPepperShop 1.4 allow remote attackers to inject arbitrary web script or HTML via the PATH_INF… | Patch early | 4.3 medium | 2.2% | 2008-12-15 |
| CVE-2006-6487 EXP | Cross-site scripting (XSS) vulnerability in index.php in DT Guestbook (dt_guestbook) 1.0f, when register_globals is enabled, allows remote attackers t… | Patch early | 5.1 medium | 2.2% | 2007-01-16 |
| CVE-2007-6374 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 2.2% | 2007-12-15 |
| CVE-2007-6597 EXP | Multiple cross-site scripting (XSS) vulnerabilities in IPortalX before Build 033 allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 2.2% | 2007-12-31 |
| CVE-2009-2588 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Hotscripts Type PHP Clone Script allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 2.2% | 2009-07-24 |
| CVE-2009-2684 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers,… | Patch early | 4.3 medium | 2.2% | 2009-10-13 |
| CVE-2009-3565 EXP | Multiple cross-site scripting (XSS) vulnerabilities in intruvert/jsp/module/Login.jsp in McAfee IntruShield Network Security Manager (NSM) before 5.1.… | Patch early | 4.3 medium | 2.2% | 2009-11-13 |
| CVE-2017-8918 EXP | XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted… | Patch early | 5.5 medium | 2.2% | 2017-09-12 |
| CVE-2013-1509 EXP | Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 7.6.2, 11.1.1.6.0, and 11.1.1.6.1 allows remote authenti… | Patch early | 4.0 medium | 2.2% | 2013-04-17 |
| CVE-2008-0814 EXP | Directory traversal vulnerability in download.php in Tracking Requirements & Use Cases (TRUC) 0.11.0 allows remote attackers to read arbitrary files v… | Patch early | 6.4 medium | 2.2% | 2008-02-19 |
| CVE-2008-2889 EXP | Directory traversal vulnerability in the FTP client in AceBIT WISE-FTP 4.1.0 and 5.5.8 allows remote FTP servers to create or overwrite arbitrary file… | Patch early | 6.8 medium | 2.2% | 2008-06-27 |
| CVE-2004-2756 EXP | Cross-site scripting (XSS) vulnerability in viewtopic.php in Xoops 2.x, possibly 2 through 2.0.5, allows remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 2.2% | 2004-12-31 |
| CVE-2005-3412 EXP | Cross-site scripting (XSS) vulnerability in Elite Forum 1.0.0.0 allows remote attackers to inject arbitrary web script or HTML via a Post Reply to a t… | Patch early | 4.3 medium | 2.2% | 2005-11-01 |
| CVE-2010-4347 EXP | The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which allows local users to gain priv… | Patch early | 6.9 medium | 2.2% | 2010-12-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt